IPIP-tunnel with 1500 MTU

Mikael Abrahamsson swmike at swm.pp.se
Thu Jan 11 19:35:13 UTC 2001


On Thu, 11 Jan 2001 Valdis.Kletnieks at vt.edu wrote:

> Why is it "not acceptable"?  Can you configure a Path MTU of 1450 to avoid
> fragmenting, or run Path MTU Discovery?

<customer location 2>
   |
our router2
   | tunnel
our net
   | tunnel
our router1
   |
<customer location 1>
   |
customers NATbox
   |
customers internetconnection
   |
another machine

The "NEED TO FRAG"-ICMPs generated by our router1 when "another machine"
sends packets with 1500 MTU size and DF flag set will be about RFC1918
adresses when "another machine" think's it's talking to the address of the
NATbox. Breaks everything.

Anyhow, P-MTUd is broken in too many places in the internet anyway.

-- 
Mikael Abrahamsson    email: swmike at swm.pp.se





More information about the NANOG mailing list